DEV Community

Cover image for Zyxel GS1900 Switches Targeted by Chinese Threat Actor in Data Theft Campaign
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Zyxel GS1900 Switches Targeted by Chinese Threat Actor in Data Theft Campaign

Summary

Zyxel GS1900 series switches are under active exploitation by a Chinese threat actor using a high-severity buffer overflow (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. The campaign has compromised government records and relies on unpatched firmware and default credentials to gain system control.

Take Action:

If you have Zyxel GS1900 series switches, make sure their management interface is isolated from the internet, accessible from trusted networks only and all default passwords are changed. Then update the firmware to version 2.90(xxxx.2)C0 or later ASAP and check the switches for signs of breach. Attackers are actively exploiting this flaw.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)